Effective date: 18 April 2026 · Last update: 18 April 2026
Data Controller
AUTH spółka z ograniczoną odpowiedzialnością (AUTH sp. z o.o.)
Marszałkowska 58 / 15, 00-545 Warszawa, Polska
KRS: 0001043319 · NIP: 5273062913 · REGON: 525652590
privacy@getup.dev
Unless stated otherwise, the party acting as data controller for the GetUp Service is:
Note: for data about the customer company's own employees or customers, the customer company is the data controller; GetUp acts as data processor.
| Category | Example data |
|---|---|
| Identity | Name, email, phone, tax ID (NIP/REGON/KRS) |
| Account | Username, password hash, TOTP secret, login logs |
| Company | Company name, sector, address, employee count, currency |
| Payment | Stripe customer ID, subscription ID (card details live in Stripe, not with us) |
| Usage | IP address, browser, event logs (Vercel Analytics) |
| Content | Employee, customer, invoice, shift data you upload |
| Communication | Support emails, quote accept/reject events |
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Providing the Service, account management | Contract (6(1)(b)) |
| Payment collection and invoicing | Contract (6(1)(b)) + Legal obligation (6(1)(c)) |
| Accounting and tax | Legal obligation (6(1)(c)) |
| Security, fraud prevention | Legitimate interest (6(1)(f)) |
| Marketing (newsletter) | Consent (6(1)(a)) — only if you opt in |
| Product improvement, statistics | Legitimate interest (6(1)(f)), anonymized |
We rely on the following sub-processors to provide the Service. A GDPR Art. 28 compliant DPA is or will be in place with each.
| Provider | Purpose | Location |
|---|---|---|
| Google LLC (Firebase) | Database, authentication, hosting | USA (SCC) |
| Vercel Inc. | Server hosting, CDN, analytics | USA (SCC) |
| Stripe, Inc. | Payment processing | USA / Ireland (SCC) |
| Resend, Inc. | Transactional email | USA (SCC) |
| ImprovMX | Email forwarding | USA (SCC) |
Transfers to US-based providers rely on the Standard Contractual Clauses (SCC) approved by the European Commission and/or the EU-US Data Privacy Framework.
Under GDPR you have the following rights:
To exercise your rights, email privacy@getup.dev. We respond within 30 days (up to 60 for complex requests, with notice).
Per GDPR Art. 33, breaches are reported to UODO within 72 hours of detection. If the breach poses a high risk to users, they are notified directly (Art. 34).
GetUp uses strictly necessary cookies for session management, security, and preferences (e.g. getup_session). These do not legally require explicit consent. Vercel Analytics provides anonymous usage stats. You can disable cookies in your browser, but the Service will not function without strictly necessary ones.
The Service is not designed for persons under 16. We do not knowingly collect data from anyone under 16; any such data is deleted promptly upon discovery.
The sub-processors (Google, Vercel, Stripe, Resend, ImprovMX) are US-based. Transfers rely on the Standard Contractual Clauses (SCC). Where feasible, we prefer EU-region resources.
We may update this policy from time to time. Material changes are announced by email and the “Last update” date at the top of this page is revised.
Data protection: privacy@getup.dev
General support: support@getup.dev
Where this policy conflicts with applicable law, the law prevails. It is not a substitute for legal advice.